finorapersonalfinance.win
Appeared in the .win zone on Sunday, September 20, 2026; by the end of that day the census found redirects elsewhere. Full domain report
Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.
Own one of these names and think the listing is wrong? Tell us and a person will look.
What matched
Model opinions
The domain is a Cloudflare Workers app ('finora') placed behind a genuine Cloudflare Access zero-trust login gate on cloudflareaccess.com — the Cloudflare branding is the real access broker, not impersonation, and the JWT meta confirms the hostname is the legitimately configured Access application.
The domain finorapersonalfinance.win redirects to a Cloudflare Access login page claiming to be 'Log in to finora - Cloudflare Workers'. The page impersonates a Finora login portal, requesting email credentials and sending login codes via a form that posts to the attacker's infrastructure (dry-art-3009.cloudflareaccess.com). The domain name combines 'finora' with 'personalfinance', the .win TLD is high-risk for phishing, and the redirect to a fake login page with credential-capture forms is the
A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.
What the page looked like on Sunday, September 20, 2026

Same data as JSON: /api/zone/domain/finorapersonalfinance.win. This page is not indexed by search engines and does not link to the site it describes.